Skip to content

Repository files navigation

awsettings

Docs · Source · pip install awsettings · The Aither World

The Aither World is an operating system for agents — a Linux you can hand to one, the runtimes it works in, and the tools it works with. awnix is the Linux underneath it; awsettings is one of its 65 bricks — each installs on its own, runs offline, and needs no account.

Start here: Point it at your agent's settings on one machine and have them show up on the next one you open.

Your agent's permissions and config, following you to the next machine.

pip install awsettings
awsettings hook install     # and never think about it again

Your coding agent keeps its permission allowlist, its enabled tool servers and its hooks in a local file. Open a session on a second machine — a laptop, a shell on a server, a dev container your phone just spun up — and none of it is there.

So you approve the same action again. By hand. Once per surface. Forever. And the copies drift apart while every one of them looks perfectly correct.

What you get

$ awsettings status
local:  /home/you/project/.claude/settings.local.json (present)
remote: file:/home/you/.awsettings/profile.json
hooks:  PostToolUse, SessionStart
a pull would apply 2 change(s):
  + permissions.allow: Bash(python tools/deploy.py:*)
  + enabledMcpjsonServers: my-server
$ awsettings pull
applied 2 change(s) to /home/you/project/.claude/settings.local.json:
  + permissions.allow: Bash(python tools/deploy.py:*)
  + enabledMcpjsonServers: my-server

Three rules it will not break

Credentials never travel — and they are dropped by name, not by inspecting the value. A "does this look like a token" heuristic passes every secret that does not look like one, and that failure is invisible until the secret is already published. env, apiKeyHelper, awsCredentialExport, sandbox.credentials and their kin stay on the machine they were typed on. awsettings push --dry-run prints exactly what would leave.

Arrays union; they are never replaced. Two machines both edit this file. With replace semantics, machine B silently loses the rule machine A never had — and neither of them can tell. Every list here merges.

A deny is one-way. A sync may add a deny or ask rule. It may never drop one. A lost allow rule costs you a prompt; a lost deny rule costs you the thing the deny existed to prevent, quietly, on a machine whose owner still believes it is there. If you genuinely want to remove one everywhere, --prune-denies says so out loud.

It writes the personal file, not the shared one

Only .claude/settings.local.json — gitignored, yours. Never the committed .claude/settings.json, because syncing your permission allowlist into a file your team reviews as policy hands everyone rules they never approved.

Autonomy is a hook, not a daemon

awsettings hook install
  • SessionStart → pull. A new machine is stale before its first tool call, so that is when it catches up.
  • A settings write → push, debounced. A rule you approve here is on its way to the others before you have finished the thought.

No background process. A daemon is a second thing to keep alive on every surface this exists to stop hand-maintaining — and when it dies, it dies quietly, which is the same failure as the drift it was meant to fix. Both hooks end in || true: a settings sync must never be able to fail a session open, because offline is the normal state of a laptop and the correct behaviour offline is to carry on.

Where the profile lives

No account required. The default is a plain JSON file in a folder you already sync — a git repo, a drive folder, a USB stick:

export AWSETTINGS_PROFILE=~/Dropbox/awsettings.json

Or point it at any endpoint that serves a JSON object on GET and merges one on PUT:

export AWSETTINGS_URL=https://example.com/api/settings/preferences
export AWSETTINGS_TOKEN=...     # environment only — never a command-line flag,
                                # which lands in shell history and the process list

One namespace per scope. --user settings live under claude_user; each project's live under its own claude_project_<hash>, keyed by the origin remote (or the directory name; AWSETTINGS_PROJECT overrides). A pull in one repo can never merge another repo's permission rules.

Only portable keys travel. A hook entry travels only when it carries "awsettings": true or "portable": true; statusLine, autoMode, permissions.defaultMode, skipDangerousModePermissionPrompt, sshConfigs, remote, voice and every credential key stay on the machine and are refused on arrival. They name a local path or one machine's safety posture.

A transport failure is never read as "no settings": both backends raise, and the CLI exits 2 rather than merging nothing and reporting success.

A 200 is not "stored". Some endpoints wrap everything in a preferences object and read only that key; send them a bare body and they merge nothing and answer OK. The shape is detected, not assumed, and after a push the server's echo is compared with what was sent. A key the server dropped is named by path and the push exits 1:

$ awsettings --domain desk push
REFUSED: PUT https://example.com/api/settings/preferences stored the profile but DROPPED 1 key(s).
  dropped: authors.token-service

AWSETTINGS_TOKEN_FILE=~/.config/my-tool/bearer reads the token from a file some other tool already rotates. A path is not a credential, so it is safe to export.

Every enrolled device, configured at sign-in

adk enroll gives each device its own signing key, registers the public half on your device record, and runs awsettings enroll, which writes ~/.awsettings/config.json (store URL, device-registry URL, token file, sign and require-seal on) and fetches the device list. A pull then accepts a profile signed by any of your enrolled devices and refuses every other signer; a device you remove drops off at the next refresh (awsettings trust refresh, or automatically before a pull once the list is an hour old). awsettings trust list shows who is trusted.

Signed, across machines

A profile carries permissions, so a machine should apply only what you signed. Sign on the machine you edit on, and verify everywhere else:

python -c "import awseal; awseal.keygen()"             # once, on the signing machine
export AWSETTINGS_SIGN=1                               # every push is sealed (or: push --sign)

# on every machine that pulls
export AWSETTINGS_PUBLIC_KEY=<python -c "import awseal; print(awseal.public_key_hex())">
export AWSETTINGS_REQUIRE_SEAL=1                       # an unsigned profile is refused

The hooks already run pull at session start and push after edits, so once these are exported sync needs nothing else. A sealed profile travels as one opaque string ({"_sealed": "...", "_seal": "..."}), because an endpoint that deep-merges its PUTs keeps old keys and would change the signed bytes. Keys a server adds beside that string are dropped on pull and never applied. A push with --sign and no usable key exits 1 and sends nothing.

More than one settings file

The three rules are not about one file; they are about any config edited from more than one machine. A domain says how they apply to a particular file.

$ awsettings domains
claude   a coding agent's personal settings.local.json
         /home/you/project/.claude/settings.local.json (present)
         stays home: apiKeyHelper, env, sandbox.credentials, ...
desk     a desktop avatar's cast.json: bodies, voices, volume, presence, models, prompts, vision
         /home/you/.config/Desk/cast.json (present)
         stays home: voice.endpoint

claude is the default and behaves exactly as it always has. desk is a desktop avatar's cast file, and it is managed as a plain config file from any shell, script or agent — the app watches the file, so a change lands live:

awsettings --domain desk set voice.volume 0.4            # the master fader
awsettings --domain desk set 'actors."mcp:speak".volume' 1.5
awsettings --domain desk set voice.muted true            # silent, captions stay on
awsettings --domain desk get voice
awsettings --domain desk push                            # ...and on the next machine:
awsettings --domain desk pull

Two things differ from claude, each for a reason:

  • Records merge field by field. Two machines edit different fields of the same speaker. A one-level merge would let one machine's record replace the other's whole — the replace-semantics loss this tool exists to prevent.
  • Its own sync section never travels. It holds a profile path and a bearer-file path on one machine. A profile that could deliver one could re-point a machine's sync target — and the file its bearer is read from — at a server of its choosing. Never sent, refused on arrival.
  • voice.endpoint stays home, in both directions. It is not a secret; it is a fact about one machine's network. Synced to a laptop with nothing on that port, it mutes a working avatar with a config that looks correct.

memory is a memory lander's config.json: its targets, index budget, the Strata prefix it pushes under, and per project the latest sealed bundle's digest and the public key that sealed it — what a new machine needs to pull that memory back and refuse a bundle sealed by anyone else. Paths on one machine (bundle root, signing-key file) are not synced and are refused on arrival; projects merges per project.

aitherzero is AitherZero's gitignored config.local.psd1, kept as opaque text, one copy per host (status lists hosts and push times). A credential-shaped line refuses it, push and pull; a pull backs the replaced file up under ~/.awsettings/backups/. Rebuilding a dead machine:

  1. Fresh machine: clone the repo and sign in.
  2. pip install awsettings
  3. awsettings --domain aitherzero pull --host <old-hostname>

A merge cannot carry a delete, so un-setting a field everywhere is an explicit null: awsettings --domain desk set 'actors."mcp:speak".volume' null.

The mods domain: which model your coding agent's subagent runs on

~/.aither/mods.json holds the defaults a coding agent's aw subagent uses when the prompt does not name a route: which harness, which backend, which model. The mod reads it on every spawn, so a change takes effect on the next one with no restart.

awsettings --domain mods set aw.harness opencode     # the default harness
awsettings --domain mods set aw.backend kimi-k3      # a backend profile, where one binds
awsettings --domain mods get aw
awsettings --domain mods push                        # ...and on the next machine:
awsettings --domain mods pull

aw.daemon stays home in both directions, for the same reason a voice endpoint does: where a daemon listens is a fact about one machine. An unknown top-level key is refused on arrival — this file steers what a coding agent runs, so nothing a pull brings in may be a key the mod would not have written itself.

Presets: a whole Claude Code setup in one command

awsettings preset list
awsettings preset show aitherium-claude
awsettings preset apply aitherium-claude --dry-run   # print the diff, write nothing
awsettings preset apply aitherium-claude --push      # apply, then `awsettings --user push`
awsettings preset pull                               # on the next machine: `--user pull`

A preset merges the portable keys of ~/.claude/settings.json (voice, language, fallbackModel, notifications, footer links, spinner tips, output style, plugins and their marketplace) and a binding into ~/.claude/keybindings.json. It never replaces a value you already set (--force does), backs the file up first, and prints the diff. autoMode, hooks, env, permissions and credential helpers are never written: a preset naming one is refused whole, exit 1. The preset keys (all but voice) ride the ordinary user-level sync, the claude_user namespace, so applying and pushing on one machine makes them the baseline for the rest; a marketplace sourced from a local directory never leaves the machine.

Plugins are code (they bring hooks), so a pull treats them like hooks. An arriving extraKnownMarketplaces is refused unless the blob carried a seal that verified (push --sign, require_seal). An arriving enabledPlugins may always switch a plugin OFF, but may switch one ON only when its marketplace is already known here: in this machine's settings, in its plugin registry (plugins/known_marketplaces.json), or delivered by that same sealed blob. Credentials in a marketplace URL (https://user:token@host/...) are stripped both on the way out and on arrival. Every --user path honours CLAUDE_CONFIG_DIR, as Claude Code does.

Exit codes

code meaning
0 did the thing (or there was nothing to do — it says which)
1 a rule refused it
2 could not judge: profile unreachable, or a settings file would not parse

Prove it before you trust it

awsettings --self-test

Runs offline. Asserts that credentials neither leave nor arrive, that arrays union instead of replacing, that a deny is never dropped by default, that installing the hooks twice leaves one hook and does not clobber somebody else's, that a malformed settings file refuses rather than reading as empty, and that writes are atomic.

Licence

Apache-2.0.

The aw family

Standalone tools that share one idea: replace something you would otherwise have to trust with something you can check.

Each installs on its own, works offline, and needs no account.

instead of trusting you check
awdk a framework's idea of how your agents should run one loop you can read, pointed at a backend you already pay for
awskills that an agent knows your procedure the procedure written down, versioned, and loadable by any agent
awpack that the pack you want shipped inside somebody's SDK, under whatever licence that SDK happens to carry the pack as its own versioned artifact, with its own licence, that any agent runtime can install
awm that memory stayed in its lane tenant:user:project scopes, so a write cannot cross a boundary
awdesk that the agent is somewhere behind a browser tab a tray icon, a face on your desktop, and the decision card that pops when it needs you
awnode a vendor's cloud with every prompt a local gateway routing to backends you chose
awgraph that grep found everything an AST + tree-sitter call graph an agent can traverse
awgit that no one else is editing this file a lease, refused at commit time if you do not hold it
awdelphi one agent's confident take on a decision the round trace, the anonymity, and who dissents
awclassify a filename, a folder, or whoever last touched it doc_type, visibility, audience and topics, with the evidence lines that decided each
awtoll that your tooling is saving you context the measured token cost of each tool call, and what the alternative cost
awseal that the artifact came from who you think an Ed25519 seal — the key that verifies is not the key that forges
awshare that the download is intact content-addressed bundles, verified on fetch
awnest that there is a person on the other end a verdict with evidence, where "we could not tell" is not "yes"
awrena a leaderboard someone can edit, and votes nobody counted a scored duel with both answers kept, and a result bound to them
awnboard a share link anyone who sees it can use an invitation addressed to one person, for one gate, revocable
awnix that the box is what you left it as an immutable image you built, with atomic rollback
awrecover that the restore worked a restore that fully lands or does not land at all
awstorage a du you ran last month, and a peers file that says 3 TB free an inventory snapshot per node with a diff since the last one, and each tree classified re-fetchable or not
awrelay a SaaS in the middle of your agents findings, alerts and coordination over your own transport
awask that anyone read the paragraph where you asked the ask itself, with a button that steers the session that raised it
awmail a mailbox somebody else can read mail your agents send and receive over your own server
awswarm that a model either fits your GPU or it doesn't run at all a placement plan and an acquisition-probability estimate before you spend on a run
awfind one vendor's idea of the web results from whichever providers you configured
awbrowse that the page said what you were told the render, the DOM and the requests it made
awvoice that a cloud vendor may hold your audio a transcript and a wav from a service you host
awvision a filename and a caption somebody wrote what a model actually reports about the pixels
awscreen a selector that was true when the page was written the elements actually rendered, by what they look like
awbeads that a layout your users built survives the next deploy the arrangement as data you can read back, diff, and hand to another surface
awbonsai that inference always means a request left the machine a WebGPU model answering on the tab's own GPU, with a consent record logged before it ever loaded
gawbbonet the model to keep a 300-message campaign coherent by itself campaign facts recalled from scoped memory you can list and edit
aitherkvcache a vendor's quantisation defaults sub-byte KV cache kernels you can benchmark yourself
awrtifact a hand-rolled split script and a hand-edited worker manifest byte-verified parts in a release, served with Range + CORS, sizes asserted by a live gate
AitherZero a pile of scripts nobody has numbered numbered, discoverable automation with declarative playbooks
AitherConnect what a page tells your browser to do a federated search and desktop bridge you host
awreason a confident paragraph the phases it went through, and every tool call it made to get there
awrecurse that everything you pasted in was actually read which slices it opened, and what it concluded from each
awprism the first explanation that fits the ranked alternatives, and the observation that separates them
awrepl what the agent believes the value is the value, printed from the live session
awreport that the report you pasted carried no token in it a redacted report, and the duplicate it merged into instead of filing twice
awresearch a summary of pages nobody opened every claim against the source it came from
awfocus twelve terminal tabs and a bad memory one command that names every session, finds any transcript, and opens or steers the one you want
awgym that a world model learned anything from the games it saw transitions captured from real play, fed back, and the retrodiction score falling on grids it never saw
awpredict a model because it trained without erroring its prediction against a self-updating lookup, on the rows that are actually novel
awevolve that your optimisation loop is finding anything every version it kept, the score that version earned, and the edit that produced it
awsh that you already know the name of the command what it decided your line meant, before it acts on it
awmine that a session's lesson survived the session a row per outcome, a candidate per lesson, and the transcript line each one came from
awrise that a scheduled agent ran at all, and ran exactly once a durable record of every wake -- fired, skipped, overlapped or timed out -- each with its reason
awkno that the docs site is up, or that you remember the family the whole ecosystem in your terminal, with no network at all
awwall that a service only talks to the hosts you think it talks to an explicit egress allowlist, where a denial names the rule that denied it
awembed a general-purpose embedder that has never seen your code a held-out split of whole directories, scored teacher vs student vs int8
awtax a closed tax app's sealed file you can never read again a plain, provider-neutral schema of every figure, with the page it came from
awsettings (you are here) that you will remember to re-approve the same thing on every box you work from one profile, unioned rather than overwritten, with the credentials left behind
awavatar a cloud 3D vendor's opaque task id a manifest with a sha256, a licence and a rig-audit verdict per file

awnix is the ground floor — A Linux you can hand to an agent — immutable base, capabilities included.

The Aitherium ecosystem

Every repository here is public. Each publishes an aither-manifest.json beside its page, so any surface can read every sibling's — the network is browsable from any node in it.

repo what it is pages
awdk Build AI agent fleets — 3 lines, any backend, local or cloud docs
awskills Portable agent skills — self-contained procedures an agent loads on demand docs
awpack First-party agent packs — the ones we build, versioned and installable on their own docs
awm A portable, scoped agent memory docs
awdesk Aither World Desk -- the desktop body of AitherOS Online: tray, avatars, decision cards, the Living Desktop as an overlay docs
awnode A lightweight local gateway — bridges your apps to the AI backends you chose docs
awrun A priority-aware queue and dispatcher for agentic runs and ad-hoc CI builds. It also judges whether the runner pool is big enough for the queue it is draining, and can ask a host to grow it -- reserving capacity is zero-sum, so a saturated pool needs more of it, not a different share of it docs
awgraph A semantic code graph for agents — AST + tree-sitter, call graphs docs
awgit Semantic version control on top of git — edit-ops and leases docs
awdelphi Anonymous multi-round expert panels — a converged answer with a trace docs
awclassify Classify any document -- what it is, who may read it, who it is for, what it is about —
awtoll What every tool call costs you in context, measured from your own transcripts docs
awseal Sign an artifact so a stranger can verify it docs
awshare Publish an artifact and fetch it back verified docs
awdit An append-only audit trail whose gaps are DETECTABLE docs
awbac Role-based access control that fails closed and explains itself docs
awiam Who is this caller? A directory and session store that fails honestly docs
awtunnel Reach a service that has no public address docs
awnest Prove there is a human before you let them into the nest docs
awrena Put two agents head to head and get a verdict you can check docs
awnboard A front gate you can put in front of anything, and hand someone the key to docs
awnix A Linux you can hand to an agent — immutable base, capabilities included docs
awrecover Labelled snapshots with an all-or-nothing restore docs
awstorage Every drive on every node, indexed, classified and diffed -- so you can see what you own before you delete it docs
awrelay Portable agent messaging — findings, alerts, coordination docs
awask Your agent asks you a question — and acts on your answer docs
awmail Give an agent an email address — send, and actually receive docs
awnet The agentic web — agents host a mesh, and agents join one docs
awswarm Run one model too big for any single GPU across a pool of small ones —
awfind A portable search client — query, results, ranking docs
awbrowse A portable browser client — navigate, console, network, DOM, screenshot docs
awvoice Hear and speak — transcribe audio, synthesize a voice docs
awvision See an image — describe it, ask it a question, compare two docs
awscreen See this machine — what is on screen, and where to click it docs
awkit Render an agent panel from a tool result — one component, any React app —
awbeads A spatial canvas for a page — arrange things, connect them, and keep the arrangement —
awbonsai Run a real model in the visitor's own browser — no server round trip, no upload —
awknowledge How to run a coding agent so the result survives — the laws, with evidence docs
awbrain Your history as a wiki of linked markdown — claims pinned to the evidence —
gawbbonet GobboNet campaigns with a real agent brain — scoped memory, graph recall docs
aitherkvcache Near-optimal KV cache quantization for LLM inference — sub-byte compression docs
awrtifact Deliberately chunk artifacts into GitHub release assets — the productized aitherkvcache mirror lane docs
AitherZero PowerShell 7+ automation framework — numbered, self-describing scripts docs
AitherConnect Browser extension — federated AI search, page context, and the Living OS overlay docs
awreason A portable reasoning client — sessions, phases, thoughts, and the chain that produced the answer docs
awrecurse Answer a question over a context far larger than the window — recursively, with the trace kept docs
awprism Turn a failure into ranked hypotheses — and say what would confirm each one docs
awrepl A REPL an agent can actually use — state that survives between turns docs
awreport File a bug report that has already scrubbed your secrets and collapsed the duplicate —
awresearch Ask a research question, get a cited report you can check docs
awfocus See, search and steer every Claude session from one command docs
awgym An ARC training gym — a game a world model can watch, and six roles that play through it docs
awpredict Predict what your environment does next, and how surprised you were docs
awevolve Point an agent at a file and a command that scores it, and let it improve —
awsh Your terminal answers you -- type a question where a command would go docs
awmine Mine what your agents did -- outcomes, lessons and procedures out of the transcripts they left behind —
awrise Wake an agent on a schedule, let it do one thing, and put it back to sleep docs
awkno The man page for the Aither World — every brick, stack and law, offline docs
awwall Say what a workload may reach, and watch everything else fail closed docs
awrouter OpenRouter for your own fleet: pick a model backend by cost/latency/ capability, fail over, fit the context window, stream. Standalone, OpenAI-compatible, no Aither-specifics required to be valuable —
awembed Train an embedding model that knows your corpus, and prove it beats the big one docs
awtax Turn any tax PDF -- returns, W-2, 1099, statements, even scans -- into structured data you can check docs
awflow A deterministic workflow runtime — chain agent calls with journal replay and budget control docs
awsettings (you are here) Your agent's permissions and config, following you to the next machine docs
awavatar One character spec in, a rigged, animated, multi-style avatar pack out docs
<script src="aither-constellation.js"></script>

About

Your agent's permissions and config, following you to the next machine.

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages